ai · security · skills

For the function head

Your team adopted AI before you decided anything.

Track 2 · Your skills path is one click away. The story below is depth; the path names what to learn.

Build the defender’s skills

The copilots are already in your workflows.

Accountability arrived after they did — with no floor for what must be true before the AI acts alone.

22%

of AI decision-makers name internal culture and readiness their second-biggest AI concern — the gap between adopting a tool and being ready to govern what it does.

Forrester · State of AI Survey, 2025 · base 1,528 AI decision-makers

That gap has an address: your department. The tools arrived; the floor for “safe to run with less oversight” did not.

Honest answers put a floor under every step, and name the two or three moves that raise it. The hours you free are reinvested in higher-value work.

What has to be in place before I let it run with less oversight?

A 20-minute honest read of your function: where each step sits, whether its floor is met, and the moves that close the gap.

Three parts do the work. Here they are, in the order you’d use them.

The gap map

Graded on evidence, not opinion.

No self-ratings. You answer what’s actually in place — documented, standardised, measured — and the rubric places each workflow step on the maturity ladder for you.

The read is honest about scope: it measures what your function owns, and says so where it doesn’t.

The diagnostic, question by question →

Does your governance keep up?Gate open
No gate at this level — humans do the work end-to-end; AI plays no part in the loop.
Autonomy claimedL1 of 4
Governance in placeillustrative

Manual: Humans do the work end-to-end; AI plays no part in the loop.

The gate, working — watch what each autonomy rung demands before it opens.

The gate floor

What must be true before it runs alone.

Every autonomy rung has a floor: the governance categories, at the levels, that must hold before that rung is safe. Meet the floor, the gate opens. Miss it, the read tells you exactly which category is short — and by how much.

It’s a rubric you can hand to the person being graded. That’s what makes the placement defensible.

The floor table, rung by rung →

The fitted few

Two or three moves, already curated.

The read ends in a prescription, not a catalogue: the few moves matched to your weakest categories, drawn from a curated set — never a thousand-item list to wade through.

Re-run the read after the moves land, and the same instrument shows the climb.

The curated moves, by workflow →

Your reskilling list

26 controls have your name on them.

Your function’s floor, translated into jobs. Each group is work you already run; the AI era raised its bar.

19 to coordinate with a provider · 7 to verify, not build. Nobody reskills for what the provider already owns.

Set your function's floor

17 controls · 3 gate the climb

Gate the climb

1 control

Prove the function with numbers

6 controls · 2 gate the climb

Grow your people

2 controls

This is the same spine the assessment reads. Score your mastery on four concrete rungs per prompt, or run the function diagnostic — every gap lands on this list: the named skill, the group it belongs to, and who learns it.

Browse skills personalities →Run the diagnostic. Your gaps land on this list →

~12 real questions per function.

Not a 200-item audit — every question tied to a real AI Controls Matrix (AICM) control, validated at every build.

Get your function’s readSee the whole portfolio
Every number above has a method page behind it: each piece opened up as inputs → mechanism → outputs, with provenance — and the deeper tables named, content owner-gated.The method, piece by piece →

Not your role?

Each role has its own way in. Here is where the others start.